Email Header Analyzer
Paste email headers to trace the routing path, extract sender IPs with geolocation, and check SPF, DKIM, and DMARC authentication results. online email forensics tool.
- Free, no sign-up
- REST + MCP
- Updated
- Reviewed by Olgun Ozoktas
How to Get Email Headers
-
Gmail
Open the email, click the three-dot menu (⋮) in the top right, and select 'Show original'. Copy the full headers from the popup. -
Outlook
Open the email, go to File > Properties. The headers are in the 'Internet headers' box at the bottom. Select all and copy. -
Apple Mail
Open the email, go to View > Message > All Headers. Copy the displayed headers. -
Paste and analyze
Paste the copied headers into the text area above and click 'Analyze Headers' to see the routing path, authentication results, and IP geolocation data.
Common Use Cases
Phishing Detection
Email Delivery Troubleshooting
Security Investigations
Compliance Auditing
Why Analyze Email Headers?
Email Header Analyzer is a tool that parses raw email headers to reveal the complete routing history, sender authentication status, and geographic origin of any email. Every email carries hidden metadata in its headers, including the IP addresses of every server that handled the message, timestamps showing transit delays, and authentication results from SPF, DKIM, and DMARC checks.
This tool extracts and visualizes that data, geolocating each IP address to show where in the world the email traveled. It flags suspicious patterns like authentication failures, unusual routing paths, and geographic anomalies that may indicate phishing or spoofing attempts. Combine it with our IP Address Lookup for detailed analysis of specific sender IPs.
How it compares
Most email header analyzers are basic text parsers that show raw header data without context. FindUtils Email Header Analyzer goes further by geolocating every IP address in the headers, visually displaying the hop-by-hop routing path with timing data, and automatically checking SPF/DKIM/DMARC authentication results. Parsing happens in your browser; only the IP addresses found in the headers are sent to ip.findutils.com for geolocation.
Tips for Email Header Analysis
- Always copy the FULL headers, not just the visible portion. Partial headers may miss important routing information.
- Read the Received headers from bottom to top. The bottom entry is the originating server, and each subsequent entry is a hop along the delivery path.
- SPF, DKIM, and DMARC should all show 'pass' for legitimate emails. Any 'fail' result is a red flag.
- Multiple IPs from different countries in the routing path can indicate email forwarding or relay chains, but can also indicate suspicious routing.
- The sender's real IP is usually in the first (bottom-most) Received header. Headers added by intermediate servers are above it.